2026 CVE Vulnerabilities

67,274 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-92541HIGH7.2The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in...
CVE-2026-92540HIGH7.2The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users cap...
CVE-2026-92423LOW2.7The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the req...
CVE-2026-92422MEDIUM6.5The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it ...
CVE-2026-92410MEDIUM4.3The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up del...
CVE-2026-87840MEDIUM5.3The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative boo...
CVE-2026-87839HIGH7.5The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of t...
CVE-2026-87068MEDIUM6.6The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a r...
CVE-2026-87067HIGH8.5The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deser...
CVE-2026-85017HIGH7.5The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX actio...
CVE-2026-84223MEDIUM6.8The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, al...
CVE-2026-82842HIGH8.1The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming ...
CVE-2026-81654LOW3.1The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options ca...
CVE-2026-81653MEDIUM4.2The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user acting on an imag...
CVE-2026-81652LOW2.7The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is ent...
CVE-2026-81651LOW3.1The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery ...
CVE-2026-81650HIGH7.2The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of f...
CVE-2026-16542MEDIUM4.1The Import and export users and customers WordPress plugin before 2.4.5 does not validate a user-supplied URL before req...
CVE-2026-14844MEDIUM6.8The Master Slider WordPress plugin through 3.11.2 does not sanitise and escape some of its shortcode attributes before ...
CVE-2026-93965MEDIUM6.6A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops...
CVE-2026-93964MEDIUM5.3A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCe...
CVE-2026-93963MEDIUM6.3A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function...
CVE-2026-93962HIGH8.3A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_...
CVE-2026-93961MEDIUM5.3A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of...
CVE-2026-93960MEDIUM4.3A vulnerability was identified in Pixelfed up to 0.12.11. Impacted is the function instancePeers of the file app/Http/Co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now